Skip to Content.
Sympa Menu

perfsonar-user - Re: [perfsonar-user] AW: Automatic yum update changed the ssl.conf file

Subject: perfSONAR User Q&A and Other Discussion

List archive

Re: [perfsonar-user] AW: Automatic yum update changed the ssl.conf file


Chronological Thread 
  • From: Alex Hsia <>
  • To:
  • Cc: "Garnizov, Ivan (RRZE)" <>, ,
  • Subject: Re: [perfsonar-user] AW: Automatic yum update changed the ssl.conf file
  • Date: Fri, 9 Nov 2018 06:29:19 -0700
  • Ironport-phdr: 9a23:UZnP2RGVoqcIiCiiCOmt0Z1GYnF86YWxBRYc798ds5kLTJ7ypMiwAkXT6L1XgUPTWs2DsrQY07WQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbAhEmDiwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VC+85Kl3VhDnlCYHNyY48G7JjMxwkLlbqw+lqxBm3oLYfJ2ZOP94c6zTZ9MaQXdKUNhXWSJPH4iwa5IDAuoEMetesoLzpUYBrQGmCAajCuPgyD9GiHH106MnzeouDRrL0xY8E98UqnnYsMn5OaUUXOuozKfI1zLDb/ZO1Drh7IjHbB8gquyOU7JrcMre01QkGgTfgVWUt4PkMCmZ1uQWs2ia9eVtTuSvi2k9pA5ruDSvycAsipfQi48T11vK+yJ5wIMvKt25Tk52ed+kEJ1Mty6ELYt2RN0tQ312tCog1LIJpIO7cDAEyJQh3RHfb+aLc4eP4hL9TOqRLjZ4hG5leLKinBm+61Svyur5VsWsyFZKtC1Fkt7CtnAV0BzT686HSudn8ki93jaP0hjf6u9eLkApj6bUNoAuz7gtnZQQqUTOBjH6l1/qgKOKc0go5+el5uT7brjjqZKRNI55hw77P6gwhsCyBOE1PhYAUmWV/+m3yaft8lfjQLpQi/07iqnZv47eJcQcvqO5BhVa0ocn6xqmCzem0skUkWAILV5bdh+KgZLlO17JIPD/Ave/h0qjnC13yPDBO73tGpTNLn7dn7f9Zbtx9VRTxBYvwd1a+p5ZBbEMLO72V0L+t9HVDxA0Pgmqz+r7Ddhw050SVGyBD6OBNaPdq16I5uYhI+mWY48VvS7wJOIh5/Hwgn41g18dfbKo3ZQNc324GPNmLF+Dbnb2jdcBFnkKshIkTOP2kF2CTSJTZ3GqUqIk+D47EoymDZzERoCrmrOBxj63HoBNZm9YEFCBCnPod4SfW/cQcyKePNVtkj0CVbi9VYAhzxeuuxHmy7Z5NObb5DAXtY+wnORysuHUiB506iFvFMCQyUmDVHwyk28VFBEs26UqiEhw2h+jyqlxy6hREdFDofNSUw4SM5nVxqp1DM6kCVGJRcuAVFvzGobuOjo2VN9khoZWPks=

I would like to add my support for a resolution to this issue.  For Federal Government users, we are getting scanned more often by external entities and getting flagged for insecure TLS/SSL, weak ciphers and HSTS.  

Alex Hsia ==============================================================
NOAA/OAR                                            Phone: (303)497-6351
Mailstop R/ESRL                                    GVoice: (303)536-5430
325 Broadway                                  e-mail:
Boulder, CO  80305                                   PGP keyid: 8A482A90
========================================================================



On Fri, Nov 9, 2018 at 6:13 AM Doug Wussler <> wrote:

I believe this is the same issue I reported in December last year.  For that email discussion see:

 

https://lists.internet2.edu/sympa/arc/perfsonar-user/2017-12/msg00076.html

 

For the GitHub issue, see https://github.com/perfsonar/toolkit/issues/291

 

Bottom line:  The SSL.CONF file distributed with PerfSonar needs to be changed.  The SSLProtocol and SSLCipherSuite settings need to be moved outside the VirtualHost.  That way, individual deployments can override the default settings with customized configuration files.  As the file is now distributed, these settings are being place inside the VirtualHost and thus cannot be overridden by a customized config file.

 

Doug

 

 

 

Doug Wussler

Florida State University

 

 

From: <> on behalf of "Garnizov, Ivan" <>
Date: Friday, November 9, 2018 at 3:57 AM
To: Darryl K Wohlt <>, "" <>
Subject: [perfsonar-user] AW: Automatic yum update changed the ssl.conf file

 

Hello Darryl,

 

Could you please provide more information about your installation?

Is this a pS Toolkit, pS Testpoint or is this Central management deployment, other?

 

Please keep in mind, that the pS Toolkit is delivered as a full featured product to a lot of users with different skill levels and different use cases. Still to better understand your issue we need to know at least what is installed on your machine.

 

Regards,

Ivan Garnizov

 

GEANT SA1T2: pS deployments GN Operations

GEANT SA2T3: pS development team

GEANT SA3T5: eduPERT team

 

Jubiläumsjahr 2018 - IT in Bewegung

Das RRZE - der IT-Dienstleister der FAU

www.50-jahre.rrze.fau.de

 

Von: [mailto:] Im Auftrag von Darryl K Wohlt
Gesendet: Freitag, 9. November 2018 00:32
An:
Betreff: [perfsonar-user] Automatic yum update changed the ssl.conf file

 

I received an alert from our computer security group saying that my PS instance “supports the use of TLS 1.0&1.1 and/or 3DES in one or more cipher suites.”  This is a big deal at our site.

 

When I upgraded this host in late October I made sure to update ssl.conf to allow only TLSv1.2.  After this alert I checked it again, and found it was modified (replaced?) at the same time an automatic yum update occurred.  This has happened before.

 

Can we please not modify this file during updates?

 

Thanks

 

Darryl K. Wohlt

Network Architect I

 

CCD/NCS/Network Services

Fermi National Accelerator Laboratory

P.O. Box 500, MS 368

Batavia, Illinois 60510

USA

 

630 840 2901 office

630 945 5687  mobile

www.fnal.gov

 




Archive powered by MHonArc 2.6.19.

Top of Page